Jobs · Information Technology · Michigan

IT Security Specialist I

EPITEC · Detroit, MI · 3 wk ago
Information Technology$40–$45/hrContract

Rate: $40-$45/hour – Hybrid in Detroit, MI

About the Role

The EIS Compliance/Governance Analyst will assist in executing security framework compliance and governance activities. Responsibilities include documenting adherence to governance requirements across policies, standards, procedures, controls, compliance, training, and awareness, as well as preparing metrics, KPIs, and reporting materials.

Responsibilities

  • Evaluate the design and operational effectiveness of Business/IT operations against the HITRUST CSF and identify areas of improvement.
  • Interview SMEs, examine evidence documentation, analyze, and perform testing.
  • Learn company functions and processes by conducting process walkthroughs.
  • Analyze root causes of issues, provide recommendations for process improvements, and risk mitigation based on assessment findings.
  • Collaborate with cross-functional teams to mitigate risks and ensure compliance with HITRUST CSF.
  • Deliver effective and concise documentation that meets HITRUST quality standards.
  • Prepare and provide reporting such as dashboards and metrics on performance, issue analysis, and assessment statuses.
  • Utilize GRC tools to manage assessment remediation plans and documentation.
  • Serve as a HITRUST subject matter expert.
  • Participate and provide support during audits, assessments, or other required third-party reviews.
  • Support initiatives and projects.
  • Build relationships internally to foster a culture of teamwork and collaboration.

Requirements

  • At least 4–5 years of work experience in IT compliance, IT assessments, and/or IT audit, with knowledge of governance, risk, and compliance.
  • Knowledge of security and risk frameworks, standards, and best practices (e.g., HITRUST CSF, NIST CSF, ISO/IEC 27001, COBIT).
  • Self-starter with effective written and verbal communication skills and strong critical thinking abilities.
  • Experience in coordination and execution of the audit lifecycle, including evidence collection, review, observation tracking, management response collection, and auditor relations.
  • Strong problem-solving and decision-making ability.
  • Experience testing IT controls across systems, databases, applications, and operating systems.
  • Ability to frame and deliver messages based on the experience and level of the listener.
  • Strong organizational skills and ability to adjust to changing priorities while multitasking effectively.
  • Self-directed, works with minimal guidance, and proactively seeks guidance when needed.

Preferred Qualifications

  • Knowledge of Information Technology GCC and governance, risk, and compliance.
  • Experience performing audits or assessments.
  • Certified Information Systems Security Professional (CISSP), CISA, CPA/CA, CISM, or other equivalent professional certification.

Education

  • Undergraduate university degree (4-year) preferred but not required.
  • Master’s degree (e.g., MBA, MSIS, MIS) preferred but not required.
  • Five years of combined IT experience, including two years of IT security work.
  • Experience in Information Security, IT general controls, IT compliance, IT assessments, and/or IT audit.

Similar jobs